Meta Paid $78K After Bug Exposed Support Data

Meta paid $78,000 to researcher Rony K Roy after he reported a January 2026 vulnerability that exposed customer support cases, messages, files and contact details.

Meta paid $78,000 to security researcher Rony K Roy after he reported a vulnerability in January 2026 that exposed customer support cases and related data in its backend support systems.

Roy first identified what he believed was an authorization problem in Meta Horizon Managed Solutions, the enterprise platform for managing Meta Quest devices and users. Further analysis showed the issue extended into shared backend support infrastructure. Roy reported the flaw to Meta in January and reported that patches were rolled out in April; he also reported no signs of exploitation before the fixes.

The flaw combined missing authorization checks, broken access controls and insecure direct object references. When those weaknesses were chained, an attacker could enumerate support case numbers and retrieve full support requests.

According to Roy’s findings, the exposed data included email and chat exchanges between users and support agents, support case details, files uploaded to support tickets, and personal or contact information shared with support. Beyond reading case materials, an attacker could create or modify support records, including opening requests on behalf of organizations using Meta Horizon Managed Solutions, changing case status and workflows, and adding unauthorized subscribers to ongoing cases.

Roy disclosed his findings publicly last week and reported receiving a $78,000 bug bounty from Meta. His name appears on Meta’s 2026 bug bounty leaderboard. Meta did not respond to a request for comment.

Bug bounty programs award payments and recognition to researchers who identify and report security flaws. Roy’s report highlights how missing authorization checks and IDOR issues in support systems can expose customer data and allow manipulation of support records.

Articles by this author